Executive brief
A security vulnerability in Google Chrome on Linux and ChromeOS could allow a malicious website to access data from other websites. This occurs due to a flaw in how the browser handles Cross-Origin Resource Sharing (CORS), which is a security mechanism designed to prevent unauthorized data sharing between different domains. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the exposure of sensitive user information.
Technical details
An inappropriate implementation vulnerability exists in the Cross-Origin Resource Sharing (CORS) mechanism of Google Chrome for Linux and ChromeOS. The flaw allows a remote attacker to bypass origin-based security restrictions and leak data from other origins. To exploit the vulnerability, an attacker must entice a user to visit a malicious website containing a specially crafted HTML page. Successful exploitation results in the unauthorized retrieval of cross-origin data, though it does not typically allow for code execution or system modification. The issue is addressed in Chrome version 148.0.7778.168.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-05-12: patched: Stable channel update released for desktop.
- 2026-05-14: disclosed: CVE published to NVD.